Privacy Policy
We value your privacy. This website uses no tracking, analytics, or advertising cookies whatsoever. Only technically necessary data is processed, as described below.
Last updated: August 2026
This policy is also available in German: Datenschutzerklärung. Both versions are intended to have the same content; the German original governs in case of discrepancies.
1. Controller
IT Management Nord GmbH
Alter Kirchweg 77b, 25474 Hasloh, Germany
Phone: +49 4106 797054 · Email: info@itmnord.de
For matters concerning data protection only — such as exercising your rights as a data subject — you can reach us at datenschutz@itmnord.de.
No data protection officer has been appointed; the address given reaches the office responsible for data protection matters.
2. Hosting and server log files
This website runs on a web server that we operate ourselves. The underlying virtual server (vServer) is rented from STRATO AG and is located in a data centre in Germany. The provider's address is Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. Setup, configuration, and operation of the web server are entirely our responsibility; STRATO AG provides the virtualised infrastructure only. A data processing agreement pursuant to Art. 28 GDPR is in place with STRATO AG for those cases in which access to personal data cannot be ruled out while the infrastructure is provided.
This is a static site with no database, content management system, or contact form. When you visit the site, our web server automatically records technical connection data in server log files:
- IP address
- date and time of access
- page requested
- volume of data transferred
- browser and operating system used
Recording this data is technically necessary for every website visit. We process it to ensure stable and secure operation. The legal basis is our legitimate interest in the security and stability of the web server (Art. 6(1)(f) GDPR).
Log files are deleted automatically after 14 days. This period is set so that security-relevant irregularities detected only with some delay — for example attack attempts noticed only after a weekend or during an absence — can still be traced, without keeping the data longer than necessary for that purpose. We neither combine this data with other data sources nor analyse it for marketing purposes or build usage profiles from it. These safeguards are the result of the balancing test required under Article 6(1)(f) GDPR: because collection is limited to what is technically necessary, deleted again after a short period, and not analysed any further, our interest in a secure and stable operation does not override your interests, rights and freedoms requiring protection.
3. Cookies and tracking
This website uses no cookies, no analytics tools (e.g. Google Analytics), no marketing pixels, and no third-party fonts or scripts. All fonts are self-hosted and never loaded from external servers.
We store two individual values in your browser's session storage — neither is personal data, neither is transmitted to us or to third parties, and neither causes any further technology to load. Both are deleted automatically when you close the browser tab; a new visit starts unchanged, in particular the display then again follows the system setting. These are, exhaustively, all storage and access operations on this website:
- When you switch between the German and English versions, the site briefly remembers your scroll position so that you can continue reading in the same place.
- If you use the light/dark switch in the header, the site remembers your choice for the duration of the session under the name
itmn:theme. The entry contains only the value "light" or "dark". The value is never set unless you actively use the switch.
In addition, an inline script in the page header reads and deletes, once per visit, any older, permanently stored values left over from earlier versions of this website — our own legacy entry itmn:theme from before the switch to session storage, and any leftover values from a previously used anti-spam service (prefixes apbct_/ct_). This access serves cleanup purposes only and does not create any new data itself.
Because both storage operations are strictly necessary for the function you requested in each case, they are permitted without consent under section 25(2) no. 2 TDDDG — no cookie banner is required for them.
4. Contacting us
If you contact us by phone or email, we process the data you provide — such as your name, your contact details and the content of your inquiry — solely to handle your request.
Where your inquiry concerns entering into or performing a contract, the legal basis is Art. 6(1)(b) GDPR (pre-contractual measures and performance of a contract). For all other inquiries we base the processing on Art. 6(1)(f) GDPR. Our legitimate interest lies in answering incoming inquiries and keeping a traceable record of the correspondence. This processing is necessary for that purpose: without using the data you provide we could not answer your inquiry, and no less intrusive alternative is available to us. Because you initiated the contact yourself, we use the data solely to answer it, do not combine it with other data sources, and do not pass it on to third parties, our interest in orderly handling does not override your interests, rights and freedoms requiring protection.
Providing your contact details is neither required by law nor by contract and is entirely voluntary. Without them, however, we cannot answer your inquiry.
For receiving email, we use a separate mail product from STRATO AG (address given in section 2). Where access by STRATO AG to personal data cannot be ruled out in that context, a data processing agreement under Art. 28 GDPR is likewise in place; STRATO AG is a recipient within the meaning of Art. 4(9) GDPR in this respect. Where your inquiry concerns entering into a contract, people within our company involved in further handling may also become recipients. We do not transfer data to third parties within the meaning of Art. 4(10) GDPR — i.e. to parties outside this processing — unless legally required to do so.
5. Retention period
We delete personal data from a contact inquiry no later than 6 months after your matter has been fully handled. Where the correspondence concerns entering into a contract or is relevant under German commercial or tax law, the statutory retention periods apply instead: 6 years under section 257(4) of the German Commercial Code (HGB) or 10 years under section 147(3) of the German Fiscal Code (AO); we delete the data once the relevant period has expired. Our web server’s log files are deleted automatically after 14 days (see section 2).
6. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection regarding your personal data. To exercise them, write to IT Management Nord GmbH, Alter Kirchweg 77b, 25474 Hasloh, Germany, or send an email to datenschutz@itmnord.de. You also have the right to lodge a complaint with the competent data protection supervisory authority, e.g. the Independent Centre for Privacy Protection Schleswig-Holstein (ULD).
7. Links to external providers
Some of our pages contain hyperlinks to external providers — for example map material from OpenStreetMap, image sources from Pexels/Pixabay, or the publisher of the template legal texts at e-recht24.de. These links do not load any technology by themselves; only once you click such a link does your browser send the request customary for establishing a connection, including your IP address and referring page, to that provider — in the case of OpenStreetMap, potentially outside the EU. The respective provider's privacy policy then applies to the linked page.
8. Right to object under Article 21 GDPR
Where we process personal data on the basis of legitimate interests under Article 6(1)(f) GDPR — which applies to the server log files described in section 2 and to the handling of inquiries outside contract initiation described in section 4 — you have the right to object to that processing at any time on grounds relating to your particular situation.
If you object, we will stop processing the data concerned. This applies unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.
To object, simply write to IT Management Nord GmbH, Alter Kirchweg 77b, 25474 Hasloh, Germany, or send an email to datenschutz@itmnord.de.